FILEMembers
FILE

A Decade-Old Driver Disguise Still Fools Two-Thirds of Antivirus

A resurfacing trojan masquerades internally as Windows' partmgr.sys driver while using randomized external filenames and no code-signing certificate. Only one of two new file hashes in this batch yields usable evidence; the other returns no retrievable data, leaving a single sample to carry the entire update.

Oct 1, 2026, 22:58 (UTC+9)Last seenOct 1, 2026Severity72ByCTX TeamActorSmoky SpiderIOC4MITRE33RegionsUS

A trojan now resurfacing in a fresh indicator batch presents itself internally as c:\windows\system32\drivers\partmgr.sys — the Windows partition-manager driver — while the file that actually lands on disk carries a randomized name such as 7PLZfYlw8lxGk5pe1evjS.exe or N06A1Oj5m5fsNFiBO.exe. It ships with no code-signing certificate at all.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence